Data protection
Plain-language summaries first. These are placeholders — replace with counsel-reviewed text before launch.
See also the legal overview, our security practices and the data processing agreement.
Summary. For the conversations you route through the platform we act as a processor — we handle that data on your documented instructions. For your own account, billing and support records we act as a controller. Which role applies changes who owes which duties, so it is stated explicitly in the DPA.
Full text: [Insert counsel-reviewed controller/processor analysis, including joint-controller scenarios if any.]
Summary. Where the GDPR applies, our DPA is intended to carry the Article 28 terms, and personal data leaving the EEA is intended to travel under the Standard Contractual Clauses. The UK Addendum covers UK transfers.
Full text: [Insert Article 28 terms, legal bases table, transfer impact assessment summary, and the supervisory authority and EU representative under Article 27.]
Summary. We do not sell personal information and we do not share it for cross-context behavioural advertising. Where we handle personal information for a customer we intend to act as a service provider under the CPRA.
Full text: [Insert CPRA service-provider terms, consumer rights request process and verification method.]
Summary. Healthcare teams use the platform for administrative conversations. Any use involving protected health information needs a signed Business Associate Agreement in place first, and a configured boundary so clinical questions route to a person.
Full text: [Insert BAA availability, which plans include it, and the agreed scope of PHI processing. Confirm before publishing — the site currently describes the platform as HIPAA-ready, which is a different claim from HIPAA-certified.]
Summary. We use a small set of infrastructure and model providers to run the service. The DPA commits us to keeping a current list and giving notice before a new sub-processor starts processing customer data.
Current list: [Insert the actual sub-processor list — legal entity, service provided, processing location and transfer mechanism for each. Publish at /legal/sub-processors and link it here. Do not publish this page without it.]
Summary. Where data crosses a border we rely on an approved transfer mechanism rather than consent.
Full text: [Insert the transfer mechanisms actually in use, the regions data is processed in, and the region-pinning options available per plan.]
Summary. Conversation data stays available while your account is active and is deleted on a defined schedule after you close it or ask us to remove it. You can export your data at any time.
Retention schedule: [Insert the actual retention periods per data category, backup retention, and the deletion SLA after an erasure request.]
Summary. If you are an end customer of one of our customers, the fastest route is to contact them directly — they control that data and we act on their instructions. If you are our direct customer, or you cannot identify who holds your data, write to us and we will route it.
Requests: privacy@aftersales.co. [Add the DPO or privacy contact name, postal address, and the response-time commitment.]
Last updated: September 2026 · Questions: privacy@aftersales.co